US7814552B2

Method and apparatus for an encryption system

Summary by NHIP

Encryption system with server and user ends

The system records writable actions on user ends and encrypts files to prevent unauthorized information outflow. It utilizes a server database, an active directory module employing Lightweight Directory Access Protocol, and user-end code function modules that distinguish ordinary files from secure files via a secure set.

Claim Score by NHIP

Read claim 6, the broadest

Abstract

This invention relates to a method and apparatus for an encryption system. The encryption system includes a server end and user's ends, in which the whole writable action about information outflow is recorded by the server end. The method of the present invention is used for encrypting the writable file by the user's ends to avoid unauthorized information outflow through out-connecting storing equipment. Therefore, all the files are just used within the Intranet of the company and the security system. Thus, the purpose of protecting information is achieved.

US7814552B2, drawing sheet 1
Sheet 1 of 7

Term

Projected expiry 11 August 2029.

  1. Priority and filed
  2. Granted
  3. Today
  4. Projected expiry

16 claims: 2 independent, 14 dependent

  1. 1
    An encryption system, comprising a server end and least one of user's ends; the encryption system is operative to record the whole writable action by the user's ends, and encrypt writable files by the user's ends to avoid information overflow from an entrusted network; the encryption system comprising:the server end for receiving and delivering information, organizing and managing information, storing a secure set and using records of the user's ends, and updating function to surely set data at the user's ends;and database of the server end, for providing one space to store data of the server end and other input data, and directly accessing the stored data;a managing interface module, for providing an managing interface to a system operator directly to request and manage the server;an active directory module, for receiving information of company members and department groups, and for restoring database of the server end through Lightweight Directory Access Protocol (LDAP);an interface of delivering and receiving information of the user's ends, for receiving information from the user's ends, restoring information into database of the server end, and delivering information from the server end;the user's ends, which are used for receiving transmitted information, writing an ordinary file and a secure file to encrypt the information by using a single machine through the secure set, the user's ends at least comprising: a database of the user's ends, for providing one space to store data of the user's ends and input data to directly access the data;a code function module, which is a protection mechanism to avoid unauthorized outflow of information from the user's ends, for examining difference between the ordinary file and the secure file through the secure set;an interface module of the user's ends, which is an interface used for reading a writable file after acquiring the secure set, encrypting the writable file to produce a secure file by using an encryption key;after sending the secure file to an output storage equipment, the interface module of the user's ends requests the code function module to pass the secure file;a delivering data module, for delivering the secure file to the output storage equipment when the secure file passes said code function module, and delivering the encryption key to database of the server;an external accessing data module, for recording the secure file on recording medium after receiving the secure file by the output storage equipment;and a delivering and receiving data interface of the user's ends, for receiving information of the server end, restoring into database of the user's ends, and delivering information from the user's ends.
  2. 6
    Broadest claimClaim Score 46, average(NHIP)An encryption method, which is used for completely recording a plurality of whole writable steps and encrypting writable files by using an encryption key to avoid information overflow from an untreated network, the encryption method comprising steps of:setting a database of a server end, and maintaining function through a server end;the user's ends connected to the server end through the Internet by selecting various modes;the user's ends acquiring and confirming the newest data of the server end, and operative with a single machine, examining whether a command which is about writing files out into an out-connecting storage equipment exists or not;the user's ends acquiring a secure set from database of the user's ends;the user's ends examining whether the writable files are controlled according to the secure set;the user's ends encrypting and delivering the files to the out-connecting storage equipment, and the files are set as a secure file with using an encryption key;the output storage equipment storing the encrypted files on a recording medium;and storing recorded writable files and the encryption key into database of the server end.